This guide walks you through adding the Drata MCP server to Microsoft Copilot Studio so you can query Drata directly from your Copilot agent.
Prerequisites
Microsoft 365 Copilot license (Copilot Studio access)
Drata Admin role
Drata MCP OAuth configuration already set up in Drata → Settings → MCP Configuration with the scopes you want to grant
Setup Steps in Drata
Go to Settings.
Select MCP Configuration.
You must be an administrator in Drata to access this page.
Enter a name for the OAuth configuration: Microsoft Copilot MCP
Enter a description of the configuration: Drata MCP connector — securely connects Microsoft Copilot to your Drata workspace so users can query controls, risks, policies, monitoring tests, and frameworks in natural language, with role-scoped access enforced by OAuth.
Set an expiration date for the configuration: Company choice (This would require re-authentication once API keys near expiration)
Select the scopes you want to configure: Read Only for now, Drata will eventually expand to write capabilities and we can always adjust scope at a later date.
After you configure the scopes, follow the setup instructions for your specific MCP client.
Drata provides a remote hosted MCP server at:
⚠️ Important note: End users can access only the intersection of the OAuth scopes you configure and the permissions granted by their assigned roles. Users cannot access anything beyond what their roles inside the application allow while using the Drata MCP.
Learn more at MCP Configuration (New Experience).
Setup Steps in Microsoft Copilot Studio
Sign in to Copilot Studio at copilotstudio.microsoft.com.
Go to Agents and click Create → Blank agent. Name it Drata.
Open the agent. From the left nav, move off Overview to Tools (the third option).
Click Add a tool, then at the top of the dialog click Add new MCP.
Fill in the fields using the values from your Drata MCP configuration:
Server name: Drata
Server description: Drata compliance automation — query controls, risks, tests, and policies
Server URL: your regional Drata MCP endpoint
Under Authentication, select OAuth 2.0. Leave Dynamic discovery selected as the Type.
Click Create.
Sign in to Drata when prompted to authorize the connection.
Done! Copilot Studio will automatically discover the tools and resources exposed by the Drata MCP server, and you can test the agent in the preview panel right away.
Best Practices
Always mention "Drata" by name in prompts so the orchestrator routes to the MCP (e.g., "Which controls are missing evidence in Drata?").
Be specific — include framework names, time ranges, or owners when relevant.
Users only see the intersection of the OAuth scopes you configured in Drata and the permissions of their Drata role.
